Data Processing Addendum
Last updated: August 24, 2026
This Data Processing Addendum, including its annexes (the DPA), forms part of the agreement that governs Customer's use of the Zenith Analysis Service (the Agreement) between Netsky LLC, doing business as Zenith Analysis (Zenith or Processor), and the customer identified in the Agreement (Customer or Controller). It applies when Zenith Processes Customer Personal Data on Customer's behalf.
This DPA is effective on the later of the date Customer accepts the Agreement or the date the parties sign or otherwise incorporate this DPA. Capitalized terms not defined here have the meanings in the Agreement. If this DPA conflicts with the Agreement on Processing Customer Personal Data, this DPA controls. The Standard Contractual Clauses control over inconsistent provisions concerning a restricted transfer.
1. Definitions
- Applicable Data Protection Law means privacy, data-protection, and data- security laws applicable to the Processing, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and U.S. state comprehensive privacy laws.
- Customer Personal Datameans Personal Data contained in Customer Data that Zenith Processes on Customer's behalf under the Agreement.
- Data Subject, Controller, Processor, Personal Data, Process, and Supervisory Authority have the meanings in Applicable Data Protection Law.
- GDPR means Regulation (EU) 2016/679. UK GDPR has the meaning in the UK Data Protection Act 2018.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise data.
- Subprocessor means a third party engaged by Zenith to Process Customer Personal Data.
2. Roles and scope
Customer is the Controller or a Processor acting on another Controller's instructions. Zenith is the Processor or Subprocessor. Each party will comply with the obligations Applicable Data Protection Law assigns to its role. The subject matter, duration, nature, purpose, data types, and Data Subjects are described in Annex 1.
Zenith will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's configuration and use of the Service, authorized support requests, and this DPA. Zenith may also Process as required by law, in which case it will notify Customer before Processing unless law prohibits notice. If Zenith believes an instruction violates Applicable Data Protection Law, it will inform Customer and may suspend the affected Processing until the parties resolve the issue.
3. Customer responsibilities
Customer will:
- ensure its instructions and Processing comply with law and that it has all necessary rights, notices, consents, and lawful bases for Customer Personal Data;
- limit Customer Personal Data to what is adequate, relevant, and necessary for the Service;
- configure access, sharing links, integrations, retention choices, and authorized users appropriately; and
- not submit regulated or specially protected data unless the Agreement expressly permits it and the parties have agreed to any additional safeguards required by law.
4. Confidentiality and personnel
Zenith will ensure persons authorized to Process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary for their responsibilities. Zenith remains responsible for its personnel's compliance with this DPA.
5. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects, Zenith will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The current measures are summarized in Annex 2.
Customer is responsible for evaluating whether the Service and these measures meet its legal and risk requirements. Zenith may update its measures provided the overall level of protection is not materially reduced during the applicable Service term.
6. Security Incidents
Zenith will notify Customer without undue delay after confirming a Security Incident and will provide information reasonably available to help Customer meet applicable notification and remediation duties. Zenith may provide information in phases as the investigation progresses. Zenith will take reasonable steps to contain, investigate, and mitigate the incident. Notification is not an admission of fault or liability.
7. Subprocessors
Customer gives Zenith general written authorization to engage Subprocessors. Zenith will impose data-protection obligations that provide a substantially equivalent level of protection appropriate to the services they perform and remains responsible for their Processing to the extent required by Applicable Data Protection Law.
Current categories and principal providers are listed in Annex 3. Zenith may add or replace a Subprocessor. Upon written request, Zenith will provide notice of a material new Subprocessor at least 30 days before it begins Processing Customer Personal Data where reasonably practicable. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate only the affected feature or Service, and Customer's exclusive remedy is a refund of prepaid fees for the unused terminated period.
8. Data Subject requests
Taking into account the nature of the Processing, Zenith will provide reasonable assistance through Service functionality or other measures so Customer can respond to Data Subject requests. If Zenith receives a request concerning Customer Personal Data, it will notify Customer and direct the requester to Customer where legally permitted. Zenith will not respond on Customer's behalf unless Customer instructs it or law requires it.
9. Compliance assistance
Taking into account the nature of Processing and information available to Zenith, Zenith will provide reasonable assistance with Customer's obligations concerning security, breach notification, data-protection impact assessments, and prior consultation with authorities. Assistance beyond standard Service functionality may be subject to reasonable fees if the need was not caused by Zenith's breach of this DPA.
10. Information and audits
Zenith will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once per year, and additionally after a confirmed Security Incident or when required by a Supervisory Authority, Customer may request relevant third-party audit reports or conduct a narrowly scoped audit. Audits must use an independent auditor bound by confidentiality, occur on reasonable advance notice during normal business hours, avoid disruption, and not expose other customers' data or Zenith trade secrets. Customer bears its audit costs unless the audit identifies a material breach by Zenith.
11. Return and deletion
During the Service term, Customer may use available features or contact Zenith to export or delete Customer Personal Data. After termination or expiration, Zenith will delete or return Customer Personal Data on Customer's request, unless law requires retention. Data may remain temporarily in restricted backups until overwritten in the ordinary course, during which this DPA continues to apply. Zenith may retain de-identified information that no longer identifies Customer or a Data Subject.
12. International transfers
Customer authorizes Zenith and its Subprocessors to Process Customer Personal Data in the United States and other countries where they operate. For a transfer subject to the GDPR that is not covered by an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses issued under Decision (EU) 2021/914 (the EU SCCs) as follows:
- Module Two applies when Customer is a Controller and Zenith is a Processor; Module Three applies when both parties are Processors.
- Clause 7 (docking) applies. In Clause 9, Option 2 (general authorization) applies with a 30-day notice period. The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and the law of the Republic of Ireland governs. Under Clause 18, the courts of Ireland have jurisdiction.
- Annexes I, II, and III of the EU SCCs are completed with Annexes 1, 2, and 3 of this DPA.
For restricted transfers under UK law, the EU SCCs as completed above are modified by and incorporate the UK Information Commissioner's International Data Transfer Addendum to the EU SCCs, version B1.0 in force March 21, 2022 (as revised under its terms). For Swiss transfers, references in the EU SCCs to the GDPR and EU law include the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and Data Subjects in Switzerland may enforce the clauses in Switzerland.
13. U.S. state privacy terms
Where U.S. state privacy law applies to Customer Personal Data, Zenith acts as Customer's processor, service provider, or contractor. Zenith will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with personal information received from another person or from Zenith's own consumer interactions, except as permitted by law to provide the Service. Customer may take reasonable steps to ensure Processing is consistent with Customer's obligations and, after notice, may take reasonable steps to stop and remediate unauthorized use.
14. Liability and general terms
Each party's liability under this DPA is subject to the exclusions and limitations in the Agreement to the maximum extent permitted by law. This DPA terminates when Zenith no longer Processes Customer Personal Data, except provisions that must survive to protect retained data. Amendments must be in writing or made through an updated DPA incorporated under the Agreement. If any provision is unenforceable, the remainder continues in effect.
Annex 1 — Processing details
| Subject matter | Providing, securing, supporting, and maintaining the Service under the Agreement. |
|---|---|
| Duration | The Agreement term and the limited period afterward during which Zenith retains Customer Personal Data under Section 11. |
| Nature and purpose | Collection, import, access, organization, storage, reconciliation, transformation, analysis, generation, retrieval, transmission, support, security, export, and deletion as directed by Customer and necessary to provide the Service. |
| Data Subjects | Customer's authorized users, personnel, owners, customers, vendors, contractors, advisers, transaction counterparties, data-room participants, and other individuals whose data Customer submits or connects. |
| Personal Data | Contact, professional, account, authentication, usage, financial, accounting, transaction, banking, tax, customer, vendor, employment, communications, document, and other information Customer elects to process through the Service. |
| Sensitive data | Financial account and transaction information may be processed when Customer enables relevant features. Other sensitive or special-category data is not intended unless expressly agreed in writing. |
| Frequency | Continuous or on demand, depending on Customer's configuration and use. |
Annex 2 — Technical and organizational measures
- Access control: authenticated access, role and permission controls, least-privilege practices, and restricted administrative access.
- Encryption and secrets: encrypted network transport; encryption at rest where supported by hosting systems; and application-level protection for designated OAuth, bank, and integration tokens.
- Application security: tenant-aware authorization, input validation, dependency and vulnerability review, version control, testing, and controlled deployment.
- Availability and recovery: managed hosting protections, monitoring, backups where appropriate, and recovery procedures proportionate to the Service.
- Logging and incident response: operational and security logging, error monitoring, incident investigation, containment, remediation, and notification procedures.
- Organizational controls: confidentiality commitments, security awareness, vendor review, access revocation, data minimization, and periodic policy review.
Annex 3 — Subprocessors and connected providers
The following providers may Process Customer Personal Data depending on the features Customer uses and Zenith's configuration. Connected providers such as Intuit, Xero, and Plaid may also act independently under their own terms for portions of the Processing.
| Provider | Service |
|---|---|
| Supabase | Authentication, database, and file storage |
| Vercel | Application hosting, delivery, and performance analytics |
| Anthropic and OpenRouter-supported model providers | Optional AI document parsing, analysis, and data-room assistance |
| Stripe | Payment processing and billing |
| Plaid | Optional bank connectivity and transaction data |
| Intuit and Xero | Optional accounting-system connectivity |
| Resend | Transactional email delivery |
| Sentry | Application error and performance monitoring |
| PostHog | Product telemetry when configured |
| Advertising conversion measurement and optional model services when configured |
Contact
Data-protection questions and requests for a signed copy of this DPA may be sent to GDPR@zenithanalysis.com. See our Privacy Policy and GDPR Compliance Statement for related information.